Answer in brief
CVE-2026-68426 records a Critical severity (CVSS 9.8) vulnerability in xfrm: fix stale skb->prev after async crypto steals a GSO segment. The current sources do not mark it as known exploited. The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 9.8. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Linux/Linux (generic), Linux/Linux (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Linux/Linuxgeneric | >=f53c723902d1ac5f0b0a11d7c9dcbff748dde74e <33e1b0d25ca0d2818c635ff80e6aa0d295e08a98 || >=f53c723902d1ac5f0b0a11d7c9dcbff748dde74e <bbca7cc3b2b4b10afbfee99b81d9ee78f5423046 || >=f53c723902d1ac5f0b0a11d7c9dcbff748dde74e <3f4c3919baf0944ad96580467c302bc6c7758b00 | 33e1b0d25ca0d2818c635ff80e6aa0d295e08a98, bbca7cc3b2b4b10afbfee99b81d9ee78f5423046, 3f4c3919baf0944ad96580467c302bc6c7758b00 |
| Linux/Linuxgeneric | 4.16 | Not reported |
Published upstream
Aug 10, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 17, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 10, 2026
In the Linux kernel, the following vulnerability has been resolved: xfrm: fix stale skb->prev after async crypto steals a GSO segment skb_gso_segment() leaves the segment list head with ->prev pointing at the last segment, an invariant validate_xmit_skb_list() relies on when it sets its tail pointer (tail = skb->prev). When validate_xmit_xfrm() walks a GSO list and some segments are stolen by async crypto (->xmit() returns -EINPROGRESS), those segments are unlinked from the list but the head ->prev is never updated. If the last segment is the one stolen, the returned head still has ->prev pointing at it, even though it is now owned by the crypto engine and may be freed. validate_xmit_skb_list() later does tail->next = skb, writing through that stale pointer -- a use-after-free. Repoint skb->prev at the last retained segment before returning.
Quoted source text, attributed separately from HOL analysis.